Update allowed HTML tags in safe output sanitization #6095
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
The safe output sanitization now allows a broader set of HTML tags for better content formatting while removing potentially problematic tags.
Changes
h1-h6(headings),hr(horizontal rule),pre(preformatted text),sub/sup(subscript/superscript),table/tbody/thead/tr/td/th(table elements)details,summary,u(underline)pkg/workflow/js/sanitize_content.cjsand corresponding testsNew Allowed Tags
This affects all AI-generated content in GitHub issues, PRs, discussions, and comments created through agentic workflows.
Warning
Firewall rules blocked me from connecting to one or more addresses (expand for details)
I tried to connect to the following addresses, but was blocked by firewall rules:
https://api.github.com/user/usr/bin/gh gh api user --jq .login /ref/tags/v8 /tmp/go-build1085622423/b033/vet--log-format $name) { hasDiscussionsEnabled } } GOSUMDB GOWORK ease /opt/hostedtoolcache/go/1.25.0/xTest User -uns�� -unreachable=false /tmp/go-build1085622423/b082/vet.cfg /opt/hostedtoolcache/go/1.25.0/x64/pkg/tool/linux_amd64/vet *.ts' '**/*.json/tmp/gh-aw-compile-integration-3407499354/gh-aw(http block)/usr/bin/gh gh api user --jq .login 16/create_pull_request.js /tmp/go-build1085622423/b145/vet1d801311d0541ff56a3420d194e7b50aeebfc1ea1983662cfb111c1098e632d8-1(http block)/usr/bin/gh gh api user --jq .login -unreachable=false /tmp/go-build1085622423/b080/vet.cfg 5bf59e80a155590f348061d57d40209313b/log.json JxoI/WrPBVIMzDvAgh run 64/pkg/tool/linulist /opt/hostedtoolc--json -ato�� pload-artifact/git/ref/tags/v5 -buildtags 1/x64/bin/node -errorsas -ifaceassert -nilfunc git(http block)If you need me to access, download, or install something from one of these locations, you can either:
Original prompt
💬 We'd love your input! Share your thoughts on Copilot coding agent in our 2 minute survey.